Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7f13e427a244418…

MALICIOUS

PDF

83.1 KB Created: 2021-03-10 05:43:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5e23478d9eeeffcb636f44dec7a6592e SHA-1: ddabc1b039ae1a8009422a713470ac70b83a34f9 SHA-256: a7f13e427a244418e5db56a35e640b581aa4adc6090d8c93cce354fdd469bc56
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, many of which are suspicious and point to potentially malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. The document body, though heavily obfuscated, suggests a lure related to technical books, aiming to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=aircraft+electricity+and+electronics+thomas+eismin+pdf
    • https://cdn-cms.f-static.net/uploads/4497685/normal_60348918bfe5a.pdf
    • http://draiwenstore.online/little_wing_chords_eric_clapton1m714.pdf
    • http://logmeinnow.xyz/blauer_uniform_shirts_super_shirt2bho1.pdf
    • https://static.s123-cdn-static.com/uploads/4446492/normal_5ffada3eb8b88.pdf
    • https://cdn-cms.f-static.net/uploads/4366306/normal_60139c498c7cd.pdf
    • http://tricitysikhs.com/457000376k9m9h.pdf
    • https://cdn.sqhk.co/lewenowaxer/jehangj/rush_limbaugh_radio_stations_in_wisconsin.pdf
    • https://cdn.sqhk.co/mowukirew/HvjauZY/96686279715.pdf
    • https://static.s123-cdn-static.com/uploads/4384026/normal_5ff84a835a1e7.pdf
    • https://static.s123-cdn-static.com/uploads/4369900/normal_5fc59b923b119.pdf
    • https://cdn.sqhk.co/tajaketo/hQfllTL/ultimate_racing_2d_nintendo_switch.pdf
    • http://vvd.bar/96014234183ztq61.pdf
    • https://cdn.sqhk.co/rosafipex/huieyhc/fantasy_name_generator_elf_towns.pdf
    • https://cdn.sqhk.co/naziwixolagu/q4ifxhg/ship_simulator_2020_download.pdf
    • http://thrivewebs.com/polk_magnifi_max_3.1_review29yxa.pdf
    • https://cdn.sqhk.co/daladovum/jfpjhgi/12354396639.pdf
    • https://static.s123-cdn-static.com/uploads/4390095/normal_5fc57b4697195.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://uploads.strikinglycdn.com/files/e5c46e25-ed9b-4fa7-bfcb-cb181fb30dc0/rijijijuwitamonet.pdf
    • https://uploads.strikinglycdn.com/files/9465c953-3406-42cc-8904-a6006c893b69/how_do_you_troubleshoot_a_karcher_pressure_washer.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e1de.bin
36c913b324d18160288cbec7164be57614f99c6801a746844504816cecc51a93
pdf-font-stream PDF embedded font (sfnt) at offset 0xE1DE 5484 bytes
font_01_sfnt_off0000f46a.bin
fe56eba7724b78c91366687e23878d1140f40f7cc8a4a584a8c84610a3cfecc4
pdf-font-stream PDF embedded font (sfnt) at offset 0xF46A 10472 bytes
font_02_sfnt_off00011848.bin
487b0615b309991955544c550f5ba75bed2cf595b939ee618f8980ffa1ae7584
pdf-font-stream PDF embedded font (sfnt) at offset 0x11848 17156 bytes
font_03_sfnt_off00013143.bin
17063679c286fa03a3718eb6d0197392ac8cc8b7a2fea39873f20f851c7d5027
pdf-font-stream PDF embedded font (sfnt) at offset 0x13143 3112 bytes